ZeroHour

CVE-2019-16391

CVSS 3.1
6.5 medium
EPSS
1%p72
Published
()
Modified
Description

SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.

Vendors
spipcanonicaldebian
Products
spip, ubuntu linux, debian linux
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.